Skip to main content
Credentials

Credential スキーマ

Forward API リファレンス。

Vault credential object

作成、更新、取得、一覧、およびアーカイブの各エンドポイントはこの構造を返します。token、access_token、refresh_token、client_secret、secret_value などの Credential のシークレットは作成または更新リクエストでのみ受け付けられ、レスポンスには返されません。
フィールド型説明
idstringCredential ID with the vcred_ prefix
typestringAlways "vault_credential"
vault_idstringOwning Vault ID
authCredential auth objectSanitized auth details; secrets are never returned
display_namestring互換性フィールド。現在は常に空文字列で、永続化されません
metadataobjectCustom metadata object stored with the credential; defaults to {}
archived_atstring | nullArchive time in RFC 3339 format; null while active
created_atstringCreation time in RFC 3339 format
updated_atstringLast update time in RFC 3339 format

Identity の帰属

アカウント(または Workspace)には複数の Identity を作成できます。各 Identity は、そのアカウント(または Workspace)と連携する製品のエンドユーザーを表します。 A Credential does not store ownership separately. It inherits ownership entirely from its Vault:
  • Before accessing a Credential, the service checks its Vault against the current ownership scope. In a valid Identity scope, a Vault owned by another Identity returns 404. PAT calls without identity_id and Admin SAT calls retain the existing Owner mismatch 403. If this check fails, Credential processing does not continue.
  • Every Credential in an Identity-owned Vault is visible only to that Identity.
  • Create, list, get, update, archive, and delete Credential endpoints support the identity_id query parameter with the same semantics as Vaults. See Vault identity ownership.
identity_id is optional and is used only for Identity-owned resources. A PAT can specify it explicitly; omitting it uses the administrator scope. With SAT, issue an Identity-scoped token and do not explicitly pass this parameter; otherwise, the request returns HTTP 400.

Create credential request

フィールド型必須説明
authCredential auth objectYesCredential authentication information
metadataobjectNoCustom metadata stored with the credential; defaults to {}

Credential 更新リクエスト

auth と metadata のみを受け付け、少なくとも 1 つのフィールドが必要です。その他のフィールドを指定すると 400 invalid_request_error が返されます。
フィールド型必須説明
authobjectいいえ認証情報を部分更新します。現在の Credential タイプと一致する type を含める必要があります
metadataobject | nullいいえMerge Patch。オブジェクト内の null は対応するキーを削除し、トップレベルの null は metadata 全体を消去します
完全なフィールド制約については、Credential の更新を参照してください。

Credential auth object

auth uses type to select the authentication type. Responses never include secret fields.

static_bearer

フィールド型必須説明
typestringYesAlways "static_bearer"
mcp_server_urlstringYesMCP server URL, at most 2048 characters
tokenstringYes (request)Static Bearer token. Accepted only in create requests and never returned in responses

mcp_oauth

フィールド型必須説明
typestringYesAlways "mcp_oauth"
mcp_server_urlstringYesMCP server URL, at most 2048 characters
client_idstringYesOAuth client ID
client_secretstringYes (request)OAuth client secret. Accepted only in create requests and never returned in responses
access_tokenstringNo (request)Access token already obtained through OAuth. Accepted only in create requests and never returned in responses
refresh_tokenstringNo (request)OAuth refresh token. Accepted only in create requests and never returned in responses

environment_variable

フィールド型必須説明
typestringはい固定値 "environment_variable"
secret_namestringはい(作成リクエスト)環境変数名。[A-Za-z_][A-Za-z0-9_]* に一致する必要があり、作成後は変更できません
secret_valuestringはい(作成リクエスト)環境変数値。作成または更新リクエストで受け付けられ、レスポンスには返されません
injection_locationobjectいいえ注入位置の設定。body と header の boolean フィールドを指定できます
networkingobjectいいえネットワークアクセス制約。unrestricted、または allowed_hosts を持つ limited をサポートします
The create endpoint for the Forward Credential API defines the supported authentication types. Unlisted types return 400 invalid_request_error during creation.

List pagination fields

フィールド型説明
dataarray of Vault credential objectsRecords on the current page
has_morebooleanWhether another page is available
next_pagestring | nullForward cursor for the next page (recommended). Equals the current page's last_id when has_more=true; otherwise null
first_idstring | nullID of the first record on the current page
last_idstring | nullID of the last record on the current page
The request cursor parameters page, after_id, and before_id are mutually exclusive; providing more than one returns 400. Use page where possible; it has the same semantics as after_id.